logo

KIA KO! Web Hackers Vs. The Auto Industry Round 2

ID: 1bb3f03b-7589-5d34-8311-35668f8ef4ba

STIX ID: report--1bb3f03b-7589-5d34-8311-35668f8ef4ba

Feed Name: Security Ledger

Threat Score
75/100

Date Published: 2024-09-27

Date Updated: 2026-04-26

Author: Paul Roberts

...
...

Researchers disclosed a critical remote-access vulnerability in KIA dealer web applications (kiaconnect.kdealer.com and related APIs) that allowed attackers to retrieve owner PII and perform remote vehicle actions (lock/unlock, start/stop engine, honk, locate) by leveraging dealer account registration and generated access tokens or simply using vehicle identifiers; the team reported the issue to KIA, observed delayed remediation, and highlighted the systemic risk of single points of failure in connected-vehicle ecosystems.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.